Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pg49-wc5j-qh8j

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

GetRelativePath in ACD Incorporated CwpAPI 1.1 only verifies if the server root is somewhere within the path, which could allow remote attackers to read or write files outside of the web root, in other directories whose path includes the web root.

GetRelativePath in ACD Incorporated CwpAPI 1.1 only verifies if the server root is somewhere within the path, which could allow remote attackers to read or write files outside of the web root, in other directories whose path includes the web root.

EPSS

Процентиль: 63%
0.00442
Низкий

Связанные уязвимости

nvd
больше 23 лет назад

GetRelativePath in ACD Incorporated CwpAPI 1.1 only verifies if the server root is somewhere within the path, which could allow remote attackers to read or write files outside of the web root, in other directories whose path includes the web root.

EPSS

Процентиль: 63%
0.00442
Низкий